CVE-2026-11097 | Google Chrome up to 148.0.7778.216 on Android WebView cross-domain policy (ID 500311)
A vulnerability, which was classified as problematic, has been found in Google Chrome on Android. This vulnerability affects unknown code of the component WebView. This manipulation causes permissive cross-domain policy with untrusted domains.
This vulnerability is registered as CVE-2026-11097. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.